CVE-2026-35575

ChurchCRM is an open-source church management system. Prior to 6.5.3, a Stored Cross-Site Scripting (Stored XSS) vulnerability in the admin panel’s group-creation feature allows any user with group-creation privileges to inject malicious JavaScript that executes automatically when an administrator views the page. This enables attackers to steal the administrator’s session cookies, potentially leading to full administrative account takeover. This vulnerability is fixed in 6.5.3.
References
Configurations

Configuration 1 (hide)

cpe:2.3:a:churchcrm:churchcrm:*:*:*:*:*:*:*:*

History

09 Apr 2026, 18:47

Type Values Removed Values Added
First Time Churchcrm churchcrm
Churchcrm
CPE cpe:2.3:a:churchcrm:churchcrm:*:*:*:*:*:*:*:*
References () https://github.com/ChurchCRM/CRM/security/advisories/GHSA-gc8q-2gw7-qj7w - () https://github.com/ChurchCRM/CRM/security/advisories/GHSA-gc8q-2gw7-qj7w - Third Party Advisory

07 Apr 2026, 18:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-04-07 18:16

Updated : 2026-06-17 10:40


NVD link : CVE-2026-35575

Mitre link : CVE-2026-35575

CVE.ORG link : CVE-2026-35575


JSON object : View

Products Affected

churchcrm

  • churchcrm
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

CWE-1004

Sensitive Cookie Without 'HttpOnly' Flag